Workday, a cloud-based platform used for human capital managment and financial management, has disclosed a data breach after attackers gained access to a third-party CRM platform in a recent social engineering attack. The company said bad actors contacted employees by text or phone, pretending to be from HR or IT. Their goal was to fool staff members into giving up account access or their personal information. “We recently identified that Workday had been targeted and threat actors were able to access some information from our third-party CRM platform. There is no indication of access to customer tenants or the data…
Kirsten Doyle
In April 2025, SAP patched a critical vulnerability in NetWeaver AS Java Visual Composer. The flaw, tracked as CVE-2025-31324, allows unauthenticated remote code execution through the Visual Composer “metadata uploader” endpoint. Within weeks, proof-of-concept code appeared in public forums. Now, the exploit is no longer theoretical. Full tooling has been released. Source code is out in the open, easy to download and run. It takes little skill to weaponize. With AI assistance, even non-specialists can cause damage to systems that remain unpatched. Pathlock researchers examined the leaked exploit code. Their analysis confirms that the attack chain is simple. An attacker…
A new survey has revealed the extent to which poor coding practices are leaving UK businesses exposed. Two-thirds of senior technology leaders admitted their organisations suffered at least one breach or serious security incident in the past year. The common cause: insecure code. SecureFlag’s research found that of the 100 executives surveyed, nearly half reported facing more than one incident in twelve months. Despite the scale of the problem, 40 percent of organisations still do not require their developers to undergo regular secure coding training. “This should be a wake-up call for every business that develops software,” said Andrea Scaduto, CEO and…
A threat actor is selling secrets. Big ones. Operating under the alias Chucky_BF, the attacker has surfaced on underground forums with a staggering claim: over 15.8 million PayPal credentials for sale. The haul includes email addresses, plaintext passwords, and direct URLs to PayPal services. It’s being marketed as the “Global PayPal Credential Dump 2025.” Hackread first reported this development. The numbers are staggering. The dataset spans 1.1GB and covers accounts from email providers worldwide. But size isn’t everything here. What makes this leak particularly dangerous is its laser focus on PayPal infrastructure. These aren’t just random credentials. The records include…
Huntress analysts have tracked a fresh ransomware incident involving KawaLocker, also known as KAWA4096. The variant is new, but the method is familiar. Attackers gained access, disabled defenses, and moved to encrypt files. Ransomware families surface often. A year ago, Huntress reported on ReadText34. Just last month, a never-before-seen strain called Crux appeared. KawaLocker joins the list. According to Trustwave SpiderLabs, KawaLocker first appeared in June 2025. Its ransom note echoes Qilin. Its leak site resembles Akira. Analysts believe the similarities are meant to draw attention, not signal collaboration. The attack began on 8 August. Threat actors entered a victim’s…
The House of Commons and Canada’s cybersecurity agency are investigating a significant breach of parliamentary employee data, CBC News reports. An internal email to CBC staff on Monday 11 August said a malicious actor exploited a recent Microsoft vulnerability to gain unauthorized access to a database used to manage computers and mobile devices. The data included names, job titles, office locations, email addresses, and technical details about House-managed equipment. Some of the information was not publicly available. The email warned employees and members of Parliament to remain vigilant, as stolen details could be used in scams or to impersonate parliamentarians.…
Ransomware and infostealer threats are evolving faster than most organizations can keep pace. Security teams have invested heavily in backup and recovery systems, yet today’s most damaging attacks often bypass encryption altogether. Picus Security’s Blue Report 2025 uncovered a shift: threat actors are targeting credential theft, data exfiltration, and lateral movement, founded on stealth and persistence rather than noise. The numbers are a wake-up call. In nearly half the environments tested, at least one password hash was successfully cracked. Attempts at preventing data exfiltration fell to a low of 3%, a steep decline from 9% in 2024. One stolen credential…
Six new vulnerabilities have been found in Microsoft Windows. One is critical. All are serious. Check Point Research discovered the flaws and disclosed them privately to Microsoft. Patches were released on 12 August as part of Patch Tuesday. The risks are varied: system crashes, arbitrary code execution, and information leaks. For attackers, the attack surface is wide. For defenders, the response must be immediate. One flaw is notable beyond its severity. It may be the first publicly disclosed vulnerability in a Rust-based component of the Windows kernel. Rust was introduced to improve memory safety, a longstanding challenge in operating systems.…
In March last year, an insidious software supply chain compromise was revealed. The discovery of a backdoor in XZ Utils shook the cybersecurity world, thanks to its technical sophistication and for the bad actor’s methodical patience. A developer known as “Jia Tan” had spent two years earning trust in the XZ Utils project. The code they contributed was clean. Until it wasn’t. Hidden inside liblzma.so sat a backdoor. It came to life when a client connected to an infected SSH server. It hooked into critical cryptographic functions: RSA_public_decrypt, RSA_get0_key, and EVP_PKEY_set1_RSA, granting the attacker silent access. Debian, Fedora, and OpenSUSE…
A critical flaw in Erlang’s Open Telecom Platform is under active attack. CVE-2025-32433 carries a CVSS score of 10.0 and allows remote code execution without authentication. According to Palo Alto’s Unit 42 reseachers, it affects the platform’s native SSH daemon, used to manage hosts in telecom, 5G, and industrial systems. Bad actors can send specific SSH protocol messages to open ports and gain control before authentication completes. A patch is available in OTP versions 27.3.3, 26.2.5.11, and 25.3.2.20. Until updated, administrators are advised to disable the SSH service or restrict access to trusted sources. From May 1 to May 9,…
